> If companies make crappy software or groceries stock rotten vegetables the invisible hand of the market will take care of it and put them out of business.
The problem with IOT, routers, etc with unpatched vulnerabilities are much more akin to dumping toxic waste or spewing smog than a grocery equipment supplier making poor-quality goods. A grocer would naturally choose equipment that didn't fail and cost them inventory, but unpatched devices affect all of us, even the ones who didn't choose to purchase that equipment. And far from the invisible hand of the free market shutting them out, it actually tends to encourage this behavior (absent regulation) because it's cheaper to dump the waste in the river (not patch your known-vulnerable commercial software) than to pay to have it handled properly, and the market generally favors cheap above all else. It's a classic tragedy of the commons situation, and that's where regulations are important.
> Then there's the issue of who decides what is a vulnerability. And if you think that's obvious just read "The Old New Things" blog for many examples of "vulnerability" reports that boil down to "If I can run program with admin privilege's, I can do bad stuff". Or look at US senators and governors who think that looking at HTML is hacking.
Uh, MITRE already does that. The CVE list is a thing that exists, it works well and isn't filled with a bunch of nonsense. Some blog being bad doesn't mean there's no way to systematically track vulnerabilities and their severity.
This is nonsense throwing up your hands "who can, truly, know anything!?". We can, and we already do.
> Finally, not of that is free. Government doesn't make money, it takes it from you. So when we create new regulation that require more government employees
The beautiful thing is, this isn't about the government enforcing these regulations - this is about creating a civil claim by the customers of the business. The business will provide a support window for critical security vulnerabilities, and if they fail to meet it, they're liable just like any other support contract. It's a free market solution, in fact!